Vulnerability record · CVE-2021-38645 · published 15 September 2021
CVE-2021-38645: Microsoft Open Management Infrastructure local privilege escalation
Microsoft · Azure Automation State Configuration
CVE-2021-38645 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the agent shipped with several Azure and System Center management products. A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because OMI is widely deployed across Azure services and management tooling. The record gives no root-cause detail beyond the generic CWE-noinfo classification.
Description
Open Management Infrastructure Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high CVSS of 7.8, though it requires local access and no ransomware use is documented.
What it is
CVE-2021-38645 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the agent shipped with several Azure and System Center management products. A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because OMI is widely deployed across Azure services and management tooling. The record gives no root-cause detail beyond the generic CWE-noinfo classification.
Impact
An attacker who already has a foothold on the host can elevate to higher privileges, gaining full control over confidentiality, integrity and availability of the affected system. This enables further lateral movement or persistence within the managed environment.
Attack surface
The CVSS vector is local (AV:L), low complexity, low privileges required, and no user interaction, so the attacker must already have code execution or a session on the target host. It is not remotely reachable over the network per the supplied vector.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with a 2021-11-17 remediation due date, indicating exploitation in the wild; EPSS 30-day probability is about 2.7 percent (85th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2021-38645 as the first action.
- Inventory all hosts and Azure/System Center components running OMI, including Log Analytics agent, Azure Automation, Azure Sentinel, Azure Security Center and SCOM, and confirm patch status.
- Restrict local interactive and service account privileges on OMI-bearing hosts to limit who can reach the vulnerable component.
- Where OMI is not required, remove or disable the agent to reduce exposure.
- Track the CISA KEV due date and verify remediation through configuration management reporting.
Detection
- Monitor for unexpected privilege changes or new high-privilege processes spawned from OMI-related service processes.
- Audit OMI service and agent logs on managed hosts for anomalous local access or restart patterns.
- Alert on execution of known OMI binaries by non-administrative local accounts.
- Correlate host-level privilege escalation events with OMI agent activity across the fleet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-38645 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38645 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38645 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38645 | US Government Resource |
Track CVE-2021-38645 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38645), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.